Executive brief
Oracle One-to-One Fulfillment is a component of the Oracle E-Business Suite used for managing high-volume personalized communications. A security vulnerability in its user interface allows an attacker to trick a legitimate user into performing actions that compromise the system. If exploited, this could lead to unauthorized access to sensitive business data or the ability to modify and delete records, potentially impacting other integrated Oracle products.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is classified as an 'unspecified' vulnerability that is easily exploitable via the HTTP protocol. The attack requires human interaction from a person other than the attacker (UI:R) and results in a Scope change (S:C), suggesting a Cross-Site Scripting (XSS) or similar injection-based flaw. An unauthenticated attacker can gain unauthorized read access to all accessible data and partial update/delete privileges. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published